logo

The beginning of the end: the story of Hunters International

ID: fbdb16ce-3255-55f8-9cb1-d0ef68def144

STIX ID: report--fbdb16ce-3255-55f8-9cb1-d0ef68def144

Feed Name: Group-IB Blog

Threat Score
80/100

Date Published: 2025-04-02

Date Updated: 2026-04-28

...
...

Hunters International is a Ransomware-as-a-Service operation (possibly a rebrand of Hive) that prioritizes data exfiltration and extortion; the report details its cross-platform ransomware (Windows, Linux, FreeBSD, SunOS, ESXi, ARM), an affiliate panel that provides a 'Storage Software' exfiltration tool, victimology targeting healthcare and professional services, network infrastructure (clear-net domains, Tor services, IPs), and mapped MITRE ATT&CK techniques, and notes a shift toward an extortion-only project called World Leaks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.